When you restart after running Sysprep, the Application event log contains:
Source: Userenv Event
Event ID: 1517
User: NT AUTHORITY\SYSTEM Computer: <ComputerName>
Description: Windows saved user <DomainName\UserName> registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. This is often caused by services running as a user account, try configuring the services to run in the local system account.
This event will occur if a program or service has the registry open during a log off.
You can safely ignore this warning.